flux-controller-patch-releases
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources to generate release artifacts, which could potentially be used to inject instructions into the agent's context.
- Ingestion points: The skill fetches PR titles, descriptions, and repository metadata via
gh pr viewandgh api(Step 3 and "How To Build The Changelog Entry" section). - Boundary markers: The skill does not define specific delimiters or warnings to ignore instructions embedded in the external PR data.
- Capability inventory: The skill has the ability to modify repositories (
git commit,git tag), perform network operations (git push,gh api), and manage PR lifecycles (gh pr merge). - Sanitization: There is no evidence of filtering or sanitizing PR metadata before it is interpolated into commit messages or changelog files.
- [COMMAND_EXECUTION]: The skill executes a wide range of shell commands to automate the release workflow.
- It utilizes
gitfor branch management, tagging, and code updates. - It utilizes the GitHub CLI (
gh) for PR tracking, status polling, and API interactions, including background monitoring loops for CI and approvals.
Audit Metadata